CPAP-SG61* License Guide (April-2012) General Pricelist SKU Prefix Name Description Blades included CPAP-SG21412 CPAP-SG12610 CPAP-SG12608 CPAP-SG12607 CPAP-SG12410 CPAP-SG12408 CPAP-SG12407 CPAP-SG12210 CPAP-SG12208 CPAP-SG12207 CPAP-SG4810 CPAP-SG4808 CPAP-SG4807 CPAP-SG4610 CPAP-SG4608 CPAP-SG4607 CPAP-SG4210 CPAP-SG4208 CPAP-SG4207 CPAP-SG4205 61000 System 21412 12600 12400 12200 4800 4600 4200 Gateway - The 61000 System is the industry s fastest security appliance, offering scalable performance for data centers and telecommunication companies. It s based on a multi-d hardware platform that is capable of an unprecedented performance of more than 1 Tbps of firewall throughput, and achieves over 200 Gbps today. Even more, the ability to support 70 million concurrent connections and 600,000 sessions per second brings unparalleled performance to multi-transaction environments. 21400 is a Data Center security platform that uses acceleration technologies to deliver comprehensive security. The 21400 offers high performance with up to 100 Gbps of throughput and low latency The 12000 s, featuring multi-core security technology and high port density, are ideally suited for perimeter security of large network environments as well as business-critical internal network segments. High business continuity and serviceability are delivered through features such as hot-swappable redundant power supplies/disk drives, a Lights-Out- card, and High- Availability features such as ClusterXL and Load- Sharing. 4000 s offer complete and integrated security solutions in a compact 1U form factor. Delivering firewall throughput up to 11 Gbps and IPS throughput up to 6 Gbps, these enterprisegrade appliances deliver superior performance for their class. FW, VPN, IA, ADN, ACCL FW, VPN, IA, ADN, ACCL, MOB-5, IPS, URLF, AV, APCL, ASPM, DLP, NPM, LOGS FW, VPN, IA, ADNC, MOB-5, IPS, APCL, NPM, LOGS (8 Blades package includes also the DLP. 10 Blades package includes also AV, URLF, ASPM) FW, VPN, IA, ADNC, MOB-5, NPM, LOGS (7 s package includes also IPS and APCL, 8 Blades package includes also the IPS, APCL and DLP s. 10 Blades package includes also IPS, APCL AV, URLF, ASPM) 2 2 2 One on the device ent and Managem One on the device ent and Managem One on the device ent and Managem License is per model. License supports unlimited users. License also includes container managing up to 2 gateways. Prices do not include shipping costs. License is per model. License supports unlimited users. License also includes container managing up to 2 gateways. Prices do not include shipping costs. License is per model. License supports unlimited users. License also includes container managing up to 2 gateways. Prices do not include shipping costs. 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 1
CPAP-SG2210 CPAP-SG2208 CPAP-SG2207 CPAP-SG2205 SKU Prefix Name Description Blades included CPAP-SG5077 CPAP-SG9077 CPAP-SG11067 CPAP-SG11077 CPAP-SG11087 CPAP-IP2457 CPAP-IP1287 CPAP-IP697 CPAP-IP567 CPAP-IP397 CPAP-IP297 CPAP-IP282 CPAP-SG3078 CPAP-SG2078 CPAP-SG1078 CPAP-SG5778 CPAP-SG278 CPAP-SG138 CPAP-SG3075 CPAP-SG2075 CPAP-SG1075 CPAP-SG574 CPAP-SG272 CPAP-SG274 CPAP-SG134 CPAP-SG132 CPAP-SG86 CPAP-SG82 2200 Power-1 IP s UTM-1 Total s UTM-1 appliance Series 80 appliance The 2200 offers enterprise-grade security with leading performance in a compact desktop form factor. With its multi-core technology and six 1-gigabit Ethernet ports, the 2200 is easily capable of securing any branch office or small office. Power-1 appliances with extensive 5 package for high performance and unrivaled security: Firewall, IPSec VPN, Advanced Networking, Acceleration & Clustering and IPS. IP s are the combination of the former Nokia appliances fully integrated with software into a single solution. IP s with extensive 5 package for high performance and unrivaled security: Firewall, IPSec VPN, Advanced Networking, Acceleration & Clustering and IPS. UTM-1 appliances offer a complete unified security solution for organizations of all sizes. They combine firewall, IPSec VPN, IPS, URL filtering, anti-spam, email security, antivirus and more in a convenience, easy to deploy and easy to manage solution.. UTM-1 appliances offer a complete unified security solution for organizations of all sizes. They combine firewall, IPSec VPN, IPS and more in a convenience, easy to deploy and easy to manage solution.. UTM-1 appliances offer a complete unified security solution for remote office and branch office (ROBO). They combine firewall, IPSec VPN, IPS, URL filtering, anti-spam, email security, antivirus and more in a convenience, easy to deploy and easy to manage solution. FW, VPN, IA, ADNC, MOB-5, NPM, LOGS (7 s package includes also IPS and APCL, 8 Blades package includes also the IPS, APCL and DLP s. 10 Blades package includes also IPS, APCL AV, URLF, ASPM) FW, VPN, IPS, ACCL, ADN, APCL, IA FW, VPN, IPS, ACCL, ADN, APCL, IA (IP282 includes FW & VPN only) FW, VPN, IPS, AV, URLF, ASPM, APCL, IA, NPM, EPM, LOGS FW, VPN, NPM, EPM, LOGS (the 4 s included also APCL, IA. The 5 s includes also IPS) FW, VPN (the 6 s model includes IPS, AV, ASPM, URLF 2 2 One on the device ent and Managem One on the and device License is per model. License supports unlimited users. License also includes container managing up to 2 gateways. Prices do not include shipping costs. Lincese is per model. License is for Unlimited users. Includes 5,000 VPN-1 SecuRemote users, as well as MultiCore. Prices do not include shipping costs. License is per model. License is for unlimited users. Includes 1,000 VPN-1 SecuRemote users. License also includes container and 5 Secure Access. The 130 model can manage 1 gateway only. Models 270, 570, 1070, 2070 and 3070 can manage 2 gateways including themselves. Prices do not include shipping costs. License is per model. Includes 1,000 VPN-1 SecuRemote users.. License also includes container and 5 Check Point Secure Access. The 130 model can manage 1 gateway only. Models 270, 570, 1070, 2070 and 3070 can manage 2 gateways including themselves. Prices do not include shipping costs. License is per model. License is for unlimited users. Prices do not include shipping costs. CPUTM-EDGE VPN-1 UTM Edge A unified threat management hardware appliance that provides allin-one security including firewall, VPN, SmartDefense Service, IPS and Antivirus for enterprise branch offices and remote offices. The appliances are available with built-in secure wireless access point and/or ADSL modem. All wireless and/or ADSL models include a USB port used as a print server. N/A N/A Not licensable through UC. The product comes with a key preinstalled Licensed per number of concurrent connections. The SKU is a product key tied up to the MAC address of the appliance. Prices do not include shipping costs 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 2
CPSG-P1207 CPSG-P807 CPSG-P407i CPSG-P409 CPSG-P203U CPSG-P205U CPSG-P203 CPSG-P205i CPSG-P207i CPSG-P209 CPSG-P103 CPSG-P108 CPSG-C801 CPSG-C401 CPSG-C201 CPSG-C101 CPSB-FW CPSB-IA CPSB-VPN CPSB-MOB CPSB-WS SKU Prefix Name Description Blades included Gateway predefined system Gateway Container Firewall Identity Awareness IPSEC VPN Mobile Access Web Gateway - Software Gateways provide the most comprehensive, flexible and extensible security while keeping security operations simple and affordable. Software Blade containers are the common platform that contains all the necessary services to run the software environment. Every security gateway container comes prepopulated with a Firewall, based on awardwinning and patented FireWall-1 technology. 3 s includes FW, VPN, IPS. 5 s also includes APCL and IA. 7 s also includes ADN and ACCL. 9 s includes FW, VPN, ACCL, IPS, IA, APCL, AV, ASPM, URLF 1 or 2 Gateway - Blades Firewall Software Blade provides the highest level of security, with access control, application security, authentication and Network Address Translation (NAT) available to block unauthorized network FW 0 -- users and protect enterprise users and data. Provides granular security policy at a per user, per group and per machine level. It centralizes the management, monitoring and reporting of user actions across the internal network, its perimeter IA 0 -- and beyond. 's VPN Software Blade is an integrated software solution that provides secure connectivity to corporate networks, remote and mobile users, branch offices and business partners. The integrates access control, authentication and encryption VPN 0 -- to guarantee the security of network connections over the public Internet. Mobile Access Software Blade is the safe and easy solution to connect to corporate applications over the internet with Smartphone or PC. The solution provides enterprise-grade remote access via SSL VPN, allowing simple, safe and secure connectivity to email, calendar, contacts and corporate applications. The Web Software Blade provides a set of advanced capabilities that detect and prevent attacks launched against the Web infrastructure. The Web Software Blade delivers comprehensive protection when using the Web for business and communication. MOB 0 -- WS 0 -- 1 Centrally on the server or localy on the Gateway server SG100, SG200, SG400 and SG800 series are designed utilize 1, 2, 4 and 8 cores respectively. SG100 series is limited to 50 users. SG200 series is limited to 500 users. SG200U, SG400 and SG800 are unlimited. FW is included. Blade should be attached to a Gateway Container. Blade should be attached to a Gateway Container. Blade should be attached to a Gateway Container. Licensed per number of cuncurrent connection (devices) handled by the Gateway. Blade should be attached to a Gateway Container. Mobile Access allows connectivity from the following clients: Mobile for Smartphones, SSL VPN Portal, SNX for Windows, Mac and Linux. Mobile client for PC is coming soon. Available in R71 and above. Blade should be attached to a Gateway Container. 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 3
CPSB-ADNC CPSB-VOIP SKU Prefix Name Description Blades included CPSB-ESEC-6B CPSB-DLPP-3B CPSB-ETPR-2B CPSB-ABAV-2B CPSB-WBCL-2B CPSB-UTMP-5B CPSB-TS-XL CPSB-TS-L CPSB-TS-M CPSB-TS-S CPSB-DLP-U CPSB-DLP-1500 CPSB-DLP-500 CPSB-ABOT-XL CPSB-ABOT-L CPSB-ABOT-M CPSB-ABOT-S Advanced Networking and Cluster Voice over IP Extended package DLP Plus Package Extended Threat Protection package Anti-Malware package Web Conctrol package UTM Plus/ Total package Data Loss Prevention Anti-Bot annual The Advanced Networking and Clustering Software Blade simplifies network security deployment and management within complex and highly utilized networks, while maximizing network performance and security in multi-gbps environments. Built on top of the Software s architecture, the Advanced Networking & Clustering provides advanced routing, multicast support, QOS, ISP redundancy, Load Balancing, and Acceleration technologies. Please note that the Advanced Networking (ADN) and the Accesleration & Clustering (ACCL) should not appear in the PL unless specifically searched for (like the IAS systems). The security family enables you to deploy VoIP applications such as telephony or video. Software Blades packages Extended Software Blades Package for 1, 2 or 3 years (including IPS, URL Filtering, Application Control, Anti- Malware, Email, and DLP s) ADNC 0 -- VOIP 0 -- IPS, AV, URLF, ASPM, APCL, DLP DLP+ Software Blades Package for 1, 2 or 3 Years (including IPS, Application Control, and DLP) IPS, APCL, DLP 0 Extended Threat Protection Software Blades Package for 12, or 3 years (including IPS s and Application Control). IPS< APCL 0 Anti-Bot and Antivirus Software Blades provide a complete pre/post infection bot and malware protection, to detect and stop incoming attacks and existing infections. Uses unified Bot and virus defense, event investigation and reports, with real-time updates from ThreatCloud collaborative cybercrime-fighting network. The Web Software Blade provides a set of advanced capabilities that detect and prevent attacks launched against the Web infrastructure. The Web Software Blade delivers comprehensive Web related protections, including malicious code protector and advanced streaming inspection, to secure Web business and communications. UTM+ and Total Software Blades Package for 1, 2 or 3 years (including IPS, URL Filtering, Application Control, Anti-Malware, and Email s.) ABOT, AV 0 URLF, APCL 0 IPS, AV, URLF, ASPM, APCL Annual Software Blades Data Loss Prevention (DLP) solution helps businesses move data loss from detection to prevention by pre-emptively protecting sensitive information regulatory, confidential and proprietary from unintentional loss. Unlike other solutions that are DLP 0 -- unable to address user activity context, UserCheck technology brings a human factor to DLP by empowering users to remediate incidents in real-time while educating on DLP policies. Revolutionize bot protection: detect bot infected machines and APT attacks, prevent data theft and stop bot damages, and provide tools to investigate infections. Uses unique multi-layer discovery ABOT 0 -- technology with real-time updates from ThreatCloud collaborative cybercrime-fighting network. 0 0 -- -- -- -- -- -- Blade should be attached to a Gateway Container. Generate 2 license strings one for the Gateway container and another for the container. Voice over IP software is currently available on security gateway release R65.2.100 and is currently managed by security management R65.4 and higher. Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Avaialble in R75.40 and above Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Avaialble in R75.40 and above 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 4
CPSB-APCL-XL CPSB-APCL-L CPSB-APCL-M CPSB-APCL-S SKU Prefix Name Description Blades included Application Control annual Application Control Software Blade enables organizations to identify, allow, block or limit usage of thousands of Web 2.0 applications. The new software integrates s unique UserCheck technology to engage employees in the decision-making process, while educating them on risks and usage policies. APCL 0 -- Blades should be attached to a Gateway Container. Service s are yearly renewable s. License is per gateway. Available in R75 and above. CPSB-IPS-XL CPSB-IPS-L CPSB-IPS-M CPSB-IPS-S CPSB-URLF-XL CPSB-URLF-L CPSB-URLF-M CPSB-URLF-S CPSB-AV-XL CPSB-AV-L CPSB-AV-M CPSB-AV-S CPSB-ASPM CPAP-SM504 CPAP-SM2507 CPAP-SM5007 CPAP-SM503-EVNT CPAP-SM2503-EVNT CPAP-SM5003-EVNT CPAP-SM150-MD308 CPAP-SM150-MD508 CPAP-SM150-MD1008 CPAP-SM50-MD308 CPAP-SM50-MD508 CPAP-SM50-MD1008 CPSM-PU003 CPSM-PU007 CPSM-P2506 CPSM-P1003 CPSM-P1007 IPS annual URL Filtering annual Antivirus annual Anti-Spam & Email annual Smart-1 Smart-1 Smart-1 SmartEvent Smart-1 Multi- Domain pre-defined system The IPS Software Blade provides complete, integrated, next generation firewall intrusion prevention capabilities at multigigabit speeds, resulting in industry-leading total system security and performance. The IPS Blade provides complete threat coverage for clients, servers, OS and other vulnerabilities, malware/worm infections, and more. IPS 0 -- The URL Filtering Software Blade protects users and enterprises by restricting access to an array of potentially dangerous sites and content, blocking inappropriate Web surfing to over 20-million URLs. Pre-configured policy templates enable quick URLF 0 -- and simple deployment of policies using content categories. All content profiles are updated continually through a software update service. Extended Antivirus protection to stop viruses, worms and other malware at the gateway. Supporting millions of signatures using real-time updates from ThreatCloud collaborative cybercrimefighting AV 0 -- network. The Anti-Spam and Email Software Blade provide comprehensive protection for an organization's messaging infrastructure. A multidimensional approach protects the email infrastructure, provides highly accurate spam protection, and ASPM 0 -- defends organizations from a wide variety of virus and malware threats delivered within email. Continual updates assure that all threats are intercepted before they spread. - Smart-1 appliances deliver s market leading security management software s on a dedicated hardware platform specifically designed for mid-size and large enterprise security networks. Based on s software architecture, the line of four Smart-1 appliances are first to deliver a unified management solution for network, IPS and endpoint security with unsurpassed extensibility. NPM, EPM, LOGS & PRVS NPM, EPM, LOGS, PRVS, MNTR, UDIR & EVIN LOGS, RPRT & EVNT NPM, EPM, LOGS, PRVS, MNTR, MPTL, UDIR & EVIN - Software solutions integrate policy configuration, monitoring, logging, reporting and security event management in a single interface - helping minimize total cost of ownership. NPM, EPM LOGS. 6 s includes also MNTR, EVIN, PRVS. 7 s 1 server Blade should be attached to a Gateway Container. Service is yearly renewable. License is per gateway. Blade should be attached to a Gateway Container. Service is yearly renewable. License is per gateway. Blade should be attached to a Gateway Container. Service is yearly renewable. License is per gateway. Blade should be attached to a Gateway Container. Service is yearly renewable. License is per gateway. License is per model. License is for managing 5 gateways. License also includes MGMT HA. Prices do not include shipping costs. License is per model. License is for managing 25 or 50 gateways. License also includes MGMT HA. Prices do not include shipping costs. License is per model. License is for managing 5, 25 or 50 gateways (based on the model number). License also includes MGMT HA. Prices do not include shipping costs. License is per model. License is for managing 3, 5 or 10 Domains (based on the model number). License also includes MGMT HA. Additional Domain software can be added using the standard Software domain SKUs. License is per number of managed gateways and s (and not per cluster or per site.) High Availability configuration of the requires both primary and secondary servers to have the same container 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 5
CPSM-CU000 CPSM-C2500 CPSM-C1000 SKU Prefix Name Description Blades included CPSM-P1003-E CPSM-P2503-E CPSM-PU003-E CPSM-MD1004 CPSM-MLOGS-10 CPSM-P1001 CPSM-C500 CPSB-NPM CPSB-EPM CPSB-LOGS CPSB-MNTR CPSB-PRVS CPSB-MPTL CPSB-UDIR container pre-defined system Multi-Domain pre-defined system pre-defined system including Customer Log Module Add-on Container Expansion for additional 5 managed gateways Network Policy Policy Logging & Status Monitoring Smart Provisioning Portal User Directory Customer Log Module Enables real-time log accumulation, tracking and management on a dedicated log server for Gateways. It includes a container and a license for collecting logs from up to 10 gateways Container Expansion increases the number of managed gateways in a given container. There is no change to the installed s. includes also UDIR NPM, EPM, LOGS, GBLP LOGS - Blades Comprehensive network security policy management for Check Point gateways and s via SmartDashboard, a single, unified console. Centrally deploy, manage, monitor and enforce security policy for endpoint devices across any sized organization. Comprehensive information in the form of logs and a complete visual picture of changes to gateways, tunnels, remote users and security activities. A complete view of network and security performance, enabling fast response to changes in traffic patterns or security events. Centralized administration and SmartProvisioning of security gateways via a single management console. Extends a browser-based view of security policies to outside groups such as support staff while maintaining central policy control. Leverage LDAP-based user information stores, eliminating the risks associated with manually maintaining and synchronizing redundant data stores. LOGS 1 0 -- NPM 0 -- EPM 0 -- LOGS 0 -- MNTR 0 -- PRVS 0 -- MPTL 0 -- UDIR 0 -- Log Server Device and topology. No additional (or license) is required beyond this requirement. contianer can manage 10, 25 or Unlimited gateways and 1000, 2500 or Unlimited devices. Blade should be attached to a Container. Blade should be attached to a Container. Blade should be attached to a Container. Blade should be attached to a Container. Blade should be attached to a Container. Blade should be attached to a Container. Blade should be attached to a Container. Blade should be attached to a Container. 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 6
SKU Prefix Name Description Blades included CPSB-EVNT-INT CPSB-WKFL CPSB-EVS SmartEvent Intro SmartWorkflow SmartReporter & SmartEvent package Centralized, real-time, security event correlation and management for a single. policy change management with visual traceability and full auditability Eventia Suite package provides the benefits of Event Correlation and Reporting s EVNT-INT 0 -- WKFL 0 -- RPRT, EVNT 0 -- Blade should be attached to a Container. EVNT-INT provides centralized SmartEvent and management for the IPS, DLP or Application Control s. Blade should be attached to a Container. License of SmartWorkflow s is per number of managed gateways. EVS-C1000 and EVS-C2500 come with one correlation unit. EVS-CU000 comes with four correlation units. SmartEvent bundle size needs to match the Container size. CPSB-RPRT CPSB-EVNT SmartReporter SmartEvent Turn the vast amount of data collected from security and network devices into graphical, easy-to-understand reports. Centralized, real-time, security event correlation and management for and 3rd party devices. RPRT 0 Reporter Server EVNT 0 SmartEvent server Blade should be attached to a Container. SmartReporter and SmartEvent s can only be purchased in a package of two. License is per number of managed gateways and should match the container s size. CPSB-GBPL Check point Global Policy Enhance your security management with Global Policy software and enhanced administrator hierarchy GBPL 0 -- Blade should be attached to a Container. The required to add additional security domains.can be installed only on "standalone" Servers (and not on servers running and GWs). Should be installed only on a Container for Unlimited GWs only. CPSB-DMN200 CPSB-DMN1000 CPSB-DMNU000 CPSB-DMNVSX CPSB-DMNLOGS Domain software Additional Virtual Domains DMN 0 -- Blade should be attached to a Container. The Global Policy software is required to add additional security domains. Up to 250 security domains are support per single multi-domain server. CPSB-DMNVSX can only manage a singel VSX Virtual System. CPSG-P805-CPSM-PU007 CPSG-P405-CPSM-PU003 CPSG-P405-CPSM-P2506 CPSG-P405-CPSM-P1003 CPSG-P203-CPSM-P1003 CPSG-P203-CPSM-P303 CPSG-P103-CPSM-P303 CPSG-P103-CPSM-P203 CPAP-VSX21400-10 bundle 21400 VSX & Gateway - bundle and Gateway bundles make it easy for customers to purchase the right combination of gateway and management products in a single and affordable SKU. It includes managing a specified number of gateways and one. Both the and Gateway containers comes pre-populated with s Virtual Secuirty Gateways Can run up to 250 VSs. License is additive for increasing numbers of Virtual Systems.These products are based on NGX architecture. The appliance includes 1 year hardware warranty. 2 server or & Gateway servers SG100, SG200, SG400 and SG800 series are designed to utilize 1, 2, 4 and 8 cores respectively. SG100 series is limited to 50 users. SG200 series is limited to 500 users. SG400 and SG800 are unlimited. SM200, SM300, SM1000, SM2500, SMU000 are licensed to manage 2, 3, 10, 25 and Unlimited gateways respectively. Can run up to 250 VSs. License is additive for increasing numbers of Virtual Systems.These products are based on NGX architecture. The appliance includes 1 year hardware warranty. 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 7
SKU Prefix Name Description Blades included CPAP-VSX12600-10 CPAP-VSX12400-10 CPAP-VSX12200-5 12000 VSX 12000 VSX is a dedicated solution for multilayer, multi-domain virtualized security for multi-layer, multi-domain virtualized security. 12000 VSX provides organizations with maximum security in high-performance environments such as large campuses or data centers. Allows enterprises, data centers and service providers to consolidate up to 150 security gateways with firewall, IPsec and SSL virtual private network (VPN), intrusion prevention and URL filtering on a single device. The VSX bundle offering provides linear performance scalability with system high availability. 12600 and 12400 VSX appliances can run up to 150 VSs. 12200 VSX appliance can run up to 10 VSs. License is additive for increasing numbers of Virtual Systems.These products are based on NGX architecture. The appliance includes 1 year hardware warranty. CPPWR-VSX-APP CPPWR-VSX-ADD VSX-1 Add-on for XX VSs for VSX-1 The VSX Gateway enforces up to 250 discrete VPN-1 Power security policies on a single machine. Each VS (Virtual System) is associated with a VLAN, which is attached to an internal interface of the VSX Gateway. The additional Virtual Gateway enables automatic high availability by providing an additional Virtual Gateway. SecureXL is provided with every VSX Gateway for enhanced VPN and firewall performance. SecurePlatform Pro is included. N/A Licensed based on virtual number of systems running on a VSX gateway. The VSX-1 appliance Models 11060, 11070, 11080, 11260, 11270 and 11280 can run up to 250 VSs. The VSX-1 appliance Models 9070, 9090 can run up to 150 VSs. The VSX-1 appliance Model 3070 can run up to 10 VSs. VSX-1 appliance includes 1 year hardware warranty. CPPWR-VSX CPPWR-VSX-HA CPSG-VE4801 CPSG-VE1601 CPSG-VE801 CPAP-DLP CPIS-IPS-M CPAP-IPS CPIS-IPS-SW Power Virtual Gateway - VSX Secondary VPN- 1 Power VSX gateway for Load Sharing and High Availability Gateway Virtual Edition on Virtual System DLP-1 IPS-1 sensor IPS-1 OpenSensor The VSX Gateway enforces up to 250 discrete VPN-1 Power security policies on a single machine. Each VS (Virtual System) is associated with a VLAN, which is attached to an internal interface of the VSX Gateway. The additional Virtual Gateway enables automatic high availability by providing an additional Virtual Gateway. SecureXL is provided with every VSX Gateway for enhanced VPN and firewall performance. SecurePlatform Pro is included. Gateway - Virtualization Edition provides security within VMware virtualized environment securing virtual machines. VE provides consistent security for the virtual and physical environments, and is certified by VMware for use on ESX and ESXi servers. Dedicated Gateways The DLP appliance family offers easy deployment and activation, for immediate data loss prevention, by automatically preventing violations day-1 with over 250 pre-defined DLP policies that associate user, document and process. Users can also define their own DLP policies and rules and get better control and audit capabilities with intuitive, standalone or centralized security management. IPS-1 is a network intrusion detection and prevention system (IDS/IPS) that helps organizations secure their enterprise network and protect servers and critical data against known and unknown worms, automated malware and blended threats. N/A 1 Gateway FW 1 Gateway DLP, NPM, LOGS, EVIN, UDIR N/A 1 IPS-1 Server Licensed based on virtual number of systems running on a VSX gateway License must be of the same size as the primary VSX in the cluster. License must be used in a VSX cluster. Additional VE license is required per each instance of virtual machine running the Gateway VE. The Gateway Virtual Edition may utilize up to 2 virtual cores per virtual machine. FW is included. VE license does not count the number of 3rd party VM instances running on the host. s include a first year license for the annual DLP software. From second year onwards, it is required to re-purchase the annual. The license also includes container. IPS-1 appliance includes 1 year hardware warranty. Subscription to IPS Update Services (SmartDefense for NGX versions) is required to receive new protections. Subscription to IPS Update Services (SmartDefense for NGX versions) is required to receive new protections 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 8
SKU Prefix Name Description Blades included is the first single agent for Total CPEP-C1-1TO100. It protects endpoints and eliminates the need to CPEP-C1-101TO1000 deploy and manage multiple agents, reducing total cost of CPEP-C1-1001TO2500 ownership. Based on endpoint container and software s you container CPEP-C1-2501TOU can build your endpoint solution as required, and add additional EP-FW 1 Server s as needed in the future. CPSB-EP-FW CPSB-EP-FDE CPSB-EP-ME CPSB-EP-VPN CPSB-EP-AM CPSB-EP-WEBC CPSB-EP-TS CPSB-EP-FDE-P CPSB-EP-ME-P Firewall for 1 year Full Disk Encryption for 1 year Media Encryption for 1 year Remote Access (VPN) for 1 year Anti Malware and Program Control for 1 year WebCheck for 1 year Total package for 1 year Full Disk Encryption Media Encryption World's most proven firewall solution secures more than 200 applications, protocols and services featuring the most adaptive and intelligent inspection technology Delivers strong encryption with access control protecting data on hard drives Provides strong encryption for removable media and keeps data safe by controlling activity on ports and devices. Securely connect to corporate resources from an integrated Remote Access and client High Performance Anti malware (Anti Virus / Anti Spyware) engine. Control and protect endpoints from unwanted access of programs using Program Control and Program Advisory Patent Pending technology for Web Browsing Virtualization, protecting your from malicious drive-by-downloads Includes all s: Full Disk Encryption, Media Encryption, VPN, and WebCheck. Antimalware is also included in the annual Total. Delivers strong encryption with access control protecting data on hard drives Provides strong encryption for removable media and keeps data safe by controlling activity on ports and devices. EP-FW 0 -- EP-FDE 1 Server EP-ME 1 Server EP-VPN 1 Server EP-AM 1 Server EP-WEBC 1 Server EP-FDE, EP- VPN, EP-ME, EP- WEBC, EP-AM 5 (or 2 in R80) EP-FDE 1 Server EP-ME 1 Server Each server (or in R80 on EP management server and ) licensed per protected endpoint. An is defined as a Computer Instance in the End User License Agreement. EP FW in included contract. Comes pre-bundled with the EP container. contract. Annual software s include support, (as applied on the container). Includes the utilization in Enterprise Workplace management mode. contract. Annual software s include support, (as applied on the container). contract. Annual software s include support, (as applied on the container). contract. Annual software s include support, (as applied on the container). contract. Annual software s include support, (as applied on the container). contract. Annual software s include support, (as applied on the container). Includes all endpoint s, including Anti Malware. contract. Includes the utilization in Enterprise Workplace management mode. contract. 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 9
SKU Prefix Name Description Blades included CPSB-EP-VPN-P CPSB-EP-WEBC-P CPSB-EP-TS-P CPEP-VW CPEP-VW Remote Access (VPN) WebCheck Total package Abra Go Securely connect to corporate resources from an integrated Remote Access and client Patent Pending technology for Web Browsing Virtualization, protecting your from malicious drive-by-downloads Includes all s: Full Disk Encryption, Media Encryption, VPN, and WebCheck. Abra puts your office in your pocket, with a secure virtual workspace that instantly turns any PC into your own corporate desktop, allowing users to access files and applications anywhere, anytime - without the weight of bulky laptops or work files. GO puts your office in your pocket, with a secure virtual workspace that instantly turns any PC into your own corporate desktop, allowing users to access files and applications anywhere, anytime - without the weight of bulky laptops or work files. EP-VPN 1 Server EP-WEBC 1 Server EP-FDE, EP- VPN, EP-ME, EP- WEBC 4 (or 2 in R80) N/A N/A N/A Each server (or in R80 on EP management server and ) contract. contract. contract. Abra is licensed per Abra USB unit. Abra is centrally managed from Smart Dashboard when used with VPN solutions. Minimum Order Quantity of 10 units. GO ships with pre-packaged license, no licensing operations are required 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 10
High End Solutions SKU Prefix Name Description Additive CPPR-MDS-MC Provider-1 MDS Manager and Container Provider-1 Multi Domain Servers (MDS) enable one-click centralized policy distribution with centralized resilient security SmartCenter for a specified number of Customer SmartCenter Add-ons (CMAs) on a single hardware platform. Each MDS system consists from 2 basic parts: MDS Manager & MDS Container. The Provider-1 system can manage ALL types of Customer SmartCenter Add-ons (CMAs). CPPR-MDS-C Provider-1 MDS Container Enables the addition of multiple Customer SmartCenter Add-ons (CMAs) to the MDS Server, thus allowing centralized security SmartCenter and policy distribution of VPN-1 Power Gateways for multiple Customers. Multiple MDS Container hosts can be cascaded to manage thousands of Customers in a single Provider-1 system. The Provider-1 MDS Container can contain all types of CMAs. CPPR-PRO Pro Add-on for MDS Pro Add-ons extend the ArchiTecture (SMART) by providing high end SmartCenter tools for the Provider-1 environment on the CMA level. The additional abilities includes: SmartDirectory - Powerful Integration with LDAP-based directories, SmartMap Allows visualizing the network structure in a graph view, SmartUpdate Allows remote deployment of software updates and upgrades, SmartLSM Allows large-scale management and provisioning, SmartView Monitor Advanced real-time monitoring functionality, SmartPortal Allow the web access to the CMA configuration data. The above features are licensed per CMA. CPPR-CMA CPPR-CMA-XX- HA Provider-1 CMA (Primary CMA) Provider-1 CMA HA (Secondary CMA) The Provider-1 Customer SmartCenter Add-on (CMA) utilizes Check Point s SmartCenter ArchiTecture (SMART) to enable oneclick centralized security SmartCenter and policy distribution of a specified number of VPN-1 Power Gateways, for a single Customer. Includes SmartDashboard - user interface for defining and managing the security policy and SmartView Tracker - for displaying detailed log information on all enforcement points. A CMA must be hosted within an MDS Container. CMAs of different Customers are completely isolated from each other. Provider-1 CMAs can only be used within a Provider-1 MDS Container. CPPR-CLM Customer Log Module Enables real-time accumulation, tracking and SmartCenter of logs from VPN-1 Power Gateways of one Customer. Log servers are managed at the CMA level, and are not considered part of the Provider-1 System. CPPR-MLM-C CPPR-VSX-CMA Multi-Domain Log Module MLM Virtual Systems Extension - CMA Bundles (Primary VSX-CMA) The MLM is a Container of Customer Log Modules (CLMs). It enables centralized log processing for multiple Customers on a dedicated MDS host. An MLM is recommended for larger deployments to improve performance of MDS Container hosts, by offloading their log processing functions. An MLM license cannot be added to a Provider-1 (or a SiteManager-1) MDS Container host. Enables the management of a specified number of Virtual Systems, for multiple Customers, on a Provider-1. With this product, users can define all the Primary CMAs that are needed to manage the bundled Virtual Systems and the MVSs of the VSX gateways hosting them. These CMAs are hosted on a Virtual Container, and do not require a regular MDS Container. of Strings Yes 1 MDS Server Yes 1 MDS Server Yes 1 MDS Server No 1 CMA Level No 1 Yes 1 Yes 1 MDS A stand-alone host, or cohosted on a VPN-1 Power gateway. MLM Server level, and covers all of the CLM licensing. CMA licenses are mandatory for the proper functionality of Provider-1 MDS systems. There is no need to purchase a High Availability software for the secondary MDS. Multiple MDS Container licenses can be added to the same MDS host, up to a maximum of 500 CMAs. CMA licenses are required for each CMA on the Container Needs to be installed at the CMA level Licensed per number of sites managed The Secondary CMA must be of the same size as the Primary CMA. Licensed per SmartCenter console. If hosted on non-mlm server must have own CLM license The MLM license enables all the contained CLMs. No additional CLM licenses are required. Multiple MLM licenses can be added to the same host, up to a maximum of 250 CLMs. This description is valid for VSX 2.0 and higher. Users with previous were credited with separate CKs for the: MDS Container, CMAs for managing the VSs, CMA for managing the VSX Gateway. The CMAs created within the VSX- CMA license can manage only Virtual Systems. If management of VPN-1 gateways/clusters is required, MDS Container and CMA licenses need to be purchased. 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 11
SKU Prefix Name Description Additive CPPR-VSX-CMA- HA Virtual Systems Extension - CMA Bundles (Secondary VSX-CMA) CPGX-VFF FireWall-1 GX Module FireWall-1 GX combines 's patented Stateful Inspection technology with full GPRS Tunneling Protocol (GTP) awareness. FireWall-1 GX inspects all GTP tunnel fields in the context of both the packet and the tunnel. FireWall-1 GX secures the GPRS backbone CPGX-HVFF CPGX-GMC FireWall-1 GX Secondary Module FireWall-1 GX SmartCenter when connecting to roaming partner and roaming exchanges (GRX). FireWall-1 GX also protects distributed GPRS backbone environments where operators have connections to Gateway GPRS Support Nodes (GGSNs) outside of their own network or to GGSNs that are geographically dispersed FireWall-1 GX SmartCenter provides a rich set of GTP-specific log information, including granular logging details on tunnel creation, updates and deletions. Beyond logging, a wide range of security alerting options exists as well CPPR-GX-CMA FireWall-1 GX CMA A Provider-1 Customer SmartCenter Add-on for managing an unlimited number of FireWall-1 GX Modules. Includes the Pro Add-on features for this CMA. SMP SMP-OD Portal Portal On Demand The Portal (SMP) is a SmartCenter solution for service providers that deliver Internet security to consumers and small businesses. The SMP enables service providers to create flexible service categories and to centrally manage tens of thousands of subscribers. Based on SMP, SMP On-Demand is a fully- hosted solution offering managed firewall and intrusion prevention services, always-on antivirus protection, VPN connectivity, and other value-added services SMP Web Filtering An OPSEC plug-in that allows Service Providers utilizing SMP to provide centrally managed URL filtering services to Safe@ appliances. Service based on SurfControl's Web Filter UFP product. of Strings This description is valid for VSX 2.0 and higher. Users with previous versions were credited with separate CKs for the: MDS Container, CMAs for managing the VSs, CMA for managing the VSX Gateway. No 1 Gateway Licensed for an unlimited number of gateways Licensed for an unlimited number of gateways No 1 SmartCenter No 1 CMA Level No 1 No 1 Yes 1 Licensed for an unlimited number of gateways Licensed for an unlimited number of gateways Licensed per number of appliances. Not licensable through UserCenter. Licensed per number of appliances. Not licensable through UserCenter. Licensed per user. Not licensable through UserCenter. 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 12
Home Office/Small Business Solutions of Strings A fully-integrated wireless firewall, intrusion prevention, VPN and antivirus gateway. Incorporating an 802.11b/g access point. Employing s Firewall-1 and VPN-1 technology. No N/A SKU Prefix Name Description Additive CPSB-1000NW CPSB-1000N ST-CPSB ST-SDTS-CPSB Safe@Office 1000N wireless appliance Safe@Office 1000N appliance Annual Safe@Office Support and Subscription Safe@Office Annual Support and Advanced Services A fully-integrated intrusion prevention, VPN and antivirus gateway. Incorporating an 802.11b/g access point. Employing s Firewall-1 and VPN-1 technology. No N/A Support and Subscription For Safe@Office appliances only. Includes the following: a) and firmware updates, b) Email, web and chat support, c) Telephone support in English from 8:00 AM to 5 PM US time and d) Advanced Replacment. Includes the following: Gateway antivirus updates Advanced replacement URL filtering based on category classification of web-sites Messaging and Anti Spam Updates and firmware updates Email, web and chat support Extended Hardware Warranty Dynamic DNS Monthly security reports No N/A Not licensable through UC. The product comes with a key preinstalled Not licensable through UC. The product comes with a key preinstalled Licensed per number of concurrent users Licensed per number of concurrent users The appliance MAC address is required to purchase the Support Plan. Prices are Annual fees. No N/A The appliance MAC address is required to purchase the Support and Services Plan. Prices are Annual fees. 2010 Software Technologies Ltd. All rights reserved. Classification: [Unrestricted] For everyone P. 13